nuclei-templates Releases
178 releases of projectdiscovery/nuclei-templates
- v9.8.5v9.8.5 - AWS Cloud Config Review
Introduces AWS Cloud Configuration Review templates, allowing users to scan AWS misconfigurations using the `code` protocol. Also adds various AWS EC2, S3, IAM, RDS, and CloudTrail templates.
Apr 22, 2024
- v9.8.1
Focuses on adding DAST (Dynamic Application Security Testing) templates and various CVEs across HTTP, JavaScript, and Network protocols. Includes PostgreSQL enumeration and various default login templates.
Apr 8, 2024
- v9.8.0v9.8.0 - Catch 'Em All: Network Vulnerabilities
This release focuses on expanding network vulnerability detection capabilities through the introduction of the JavaScript (JS) protocol. It adds 85 new templates, including network enumeration modules for MySQL, SMB, Redis, and POP3, alongside 8 new CVEs.
Mar 24, 2024
- v9.7.8v9.7.8 - Fishing for Phishing
A significant update adding 126 OSINT phishing detection templates contributed by @rxerium, designed to help analysts discover and study phishing campaigns.
Mar 11, 2024
- v9.7.7
Adds 82 new templates and 21 CVEs, with a focus on expanding coverage for IBM technologies and adding various exposed panels and misconfigurations.
Mar 6, 2024
- v9.7.6
Adds 49 templates and 22 CVEs, introducing code protocol CVE detection and various misconfiguration templates for SAP, Node Express, and Cloudflare.
Feb 20, 2024
- v9.7.5v9.7.5 - Local Privilege Escalation
Major release adding 106 templates, including 61 Linux Local Privilege Escalation (LPE) templates utilizing the code protocol, along with 14 CVEs.
Jan 30, 2024
- v9.7.4
Adds 6 new CVE highlights, focusing on specific vulnerabilities in 2020, 2022, 2023, and 2024.
Jan 16, 2024
- v9.7.3
Adds 45 templates and 16 CVEs, introducing code protocol CVEs, SMB enumeration via JS, and cloud enumeration templates.
Jan 14, 2024
- v9.7.2
Adds 61 templates and 25 CVEs, focusing on CVE additions and installer misconfigurations for various CMSs.
Dec 22, 2023
- v9.7.1
A maintenance release focusing on bug fixes, specifically removing a logging statement and updating an existing CVE template.
Dec 2, 2023
- v9.7.0
Adds 51 templates and 18 CVEs, introducing SSH enumeration via JS protocol and templates to detect exposed configuration files.
Dec 1, 2023
- v9.6.9
Added 73 new templates including 13 new CVEs, focusing on network and HTTP vulnerabilities. Includes detection templates for network honeypots and default logins for various databases and SSH protocols.
Nov 10, 2023
- v9.6.8
Added 79 new templates featuring 33 critical CVEs. Major focus on recent high-severity vulnerabilities like F5 BIG-IP and Citrix Bleed, plus a large batch of Log4j RCE templates for various enterprise software.
Oct 29, 2023
- v9.6.7
A minor release introducing a workflow for signing templates and adding a single new CVE template. No major feature additions or breaking changes were reported.
Oct 19, 2023
- v9.6.6
A large release with 161 templates and 99 CVEs. Highlights include critical command injection vulnerabilities in Honeywell printers and local file read issues in Java frameworks like Eclipse Mojarra.
Oct 17, 2023
- v9.6.5
Focused on critical remote code execution and authentication bypass vulnerabilities in major enterprise platforms like JetBrains TeamCity, Sitecore, and Microsoft SharePoint.
Oct 11, 2023
- v0.5.0
This release introduces a new WebSocket transport protocol and simplifies the build process by removing Linux musl support and TLS compilation for embedded platforms.
Oct 1, 2023
- v9.6.4
Introduced critical RCE and authentication bypass vulnerabilities in CMS and OA systems, notably CraftCMS and Zyxel, alongside a large number of templates for Chinese OA systems.
Sep 18, 2023
- v9.6.3
Released templates for critical vulnerabilities in network devices and CMS, including Cacti, Ivanti, and Cisco VPNs.
Sep 11, 2023